Executive brief
Rockwell Automation industrial controllers and communication modules are affected by a security flaw in how they verify digital certificates. These devices are used to manage high-speed industrial processes and safety applications in manufacturing and infrastructure. An attacker could exploit this issue to establish unauthorized connections by using certificates that have been revoked, potentially bypassing security protections designed to ensure only trusted systems can communicate with the controllers.
Technical details
A certificate revocation handling vulnerability (CWE-299) exists in several Rockwell Automation Logix controllers and EN4 communication modules. The flaw occurs when the device fails to properly validate the Certificate Revocation List (CRL) for intermediate certificates. A network-based attacker can exploit this by presenting a certificate signed by a revoked intermediate CA to establish a trusted CIP Security connection. This vulnerability specifically impacts environments where the CRL feature is enabled and intermediary certificates are in use. Fixed firmware versions have been released to address the validation logic.
Affected products
- Rockwell Automation ControlLogix 5580 V36-V37
- Rockwell Automation CompactLogix 5380 V36-V37
- Rockwell Automation GuardLogix 5580 V36-V37
- Rockwell Automation Compact GuardLogix 5380 V36-V37
- Rockwell Automation 1756-EN4TR V6.001, V7.001
Timeline
- 2026-07-14: advisory: Initial release of SD1788 by Rockwell Automation
- 2026-07-14: patched: Firmware versions V38.011 and V8.001 released to correct the issue